AWS – Introducing process check rules with AWS Config conformance packs
AWS Config conformance packs now enable the inclusion of process checks rules, in addition to AWS Config managed rules, custom rules and remediation actions. Process check rules help you track resource-agnostic tasks as part of different compliance frameworks and operational best practices. You can add process check rules to new and existing conformance pack templates in your account. Unlike other rules and remediation actions in AWS Config, which can be used to automatically evaluate the compliance of specific AWS resources, the compliance status of a process check rule is manually administered and set by you through the AWS Config console or using the PutExternalEvaluation API. Two new sample conformance pack templates for operational best practices for CIS benchmarks Level 1 and Level 2 are now available, which include process check rules to match specific controls.
Read More for the details.